*
Security The GitHub App enrollment callback trusted the installation identifier in GitHub's browser redirect without proving the caller had any authority over it, so an authenticated user could bind another organization's installation to their own and mint repository-scoped tokens against its private repositories. Enrollment now confirms the installation is visible to the person completing the flow. Deployments with
github\_app configured must supply the App's OAuth client credentials and an external URL — see the
GitHub App deployment guide.
*
Compliance Project viewers attaching a
file to manual evidence or an override got a permission error, surfaced only as "there was an error submitting the evidence". Link and checkbox evidence worked, so it looked intermittent. Anyone who can submit evidence on a project can now upload files for it.
*
Compliance Files attached to product-level overrides and manual evidence were uploaded without a scope, so they were undownloadable for every role subject to project-based access filtering while owners and administrators could still fetch them. Uploads are now scoped to the owning product, and a background job repairs the affected existing attachments.
*
Frontend The findings funnel chart on the project overview and Security tabs could exceed React's update depth and take the page down. Its chart props are now referentially stable, so an unchanged refetch no longer rebuilds the chart.
*
Compliance A requirement whose manual proof had one rejected submission alongside approved ones read as green at the requirement level but amber on the check row, with the header claiming "0 of 1 checks passing". The browser now applies the same rule as the server. The checks counter also respects evidence expiry, so an expired-but-approved proof no longer counts as passing.
*
Frontend The create-project wizard decided whether to show the repository step from GitHub App availability alone, so an organization with only GitLab connected never got the step. It now gates on source control registrations across every provider.
*
Frontend A propagated product-level override always read "Overridden in a different product", even when it came from the product being viewed. The project compliance view now says "Overridden in a product", and the note moves into a tooltip on the header badge.
*
UX Members who cannot manage integrations were shown a connect call to action they had no permission to act on.
*
UX Long manual proof titles in requirement checks were truncated to a single line; they now wrap and expand in full when the check is opened.
*
Policies The policy group sheet duplicated the header border above its inputs section, and the "how to apply" snippets offered a malformed JSON variant alongside the YAML one. The JSON variants are gone and the YAML examples copy cleanly.
*
Frontend Several detail sheets rendered their titles at page-heading size, and the product notifications sheet was noticeably wider than every other configuration sheet. Sheet typography is aligned with the design system, and the CAS backend details sheet no longer shows two close buttons.
*
CLI Trace silently pushed attestations to whichever organization an org-scoped API token belonged to, ignoring the
organization field in
.chainloop.yml. A mismatch now fails with the conflict named, and pre-push attestation setup failures are logged as warnings instead of debug.
*
CLI A batch of trace fixes: a truncated transcript line no longer fails the attestation and blocks
git push;
trace run no longer uninstalls a pre-existing trace setup, losing unpushed AI attribution with it; the generated Git hooks exit cleanly when
chainloop is not on
PATH, instead of aborting the commit; and hook installation refuses to overwrite an existing backup of your own hook.
*
CLI With an external CAS backend enabled, attestation push embedded policy evaluations both inline and by reference, so the payload carried them twice and could exceed the control plane's receive limit. The inline copy is dropped once the reference is emitted.